CVE-2026-88339
Last modified
CVE-2026-88339 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). The vulnerability occurs when cloning a PROTO default SFImage field with a NULL source pointer. An attacker can provide a specially crafted input file that triggers the condition, resulting in application crash and denial of service.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-88339?
How severe is CVE-2026-88339?
How do I fix CVE-2026-88339?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-88289GeoVision GV-LPC2211 V1.14 (260903) fails to validate attack…7.5
- CVE-2026-8829HTML::Entities versions before 3.84 for Perl read freed heap…7.5
- CVE-2026-88290GeoVision GV-LPC2211 V1.14 (260903) allows unauthenticated c…7.5
- CVE-2026-8830A flaw was found in Keycloak. An authenticated user can bypa…4.3
- CVE-2026-8832The WPCode - Insert Headers and Footers + Custom Code Snippe…8.8
- CVE-2026-8833Improper neutralization of HTML-encoded characters in the UR…5.4
- CVE-2026-8834IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vuln…8
- CVE-2026-88340An invalid pointer release vulnerability exists in YARA 4.5.…7.6
- CVE-2026-88341A reachable assertion vulnerability exists in YARA 4.5.8 whe…5.5
- CVE-2026-88344An out-of-bounds read vulnerability exists in the schema lex…7.5
- CVE-2026-88345An out-of-bounds read vulnerability exists in the schema lex…7.5
- CVE-2026-8835IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointe…7.3
Are you affected by CVE-2026-88339?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
